typeanalysisfamilyacrstealerconfidencehighcreated2026-08-17updated2026-08-17infostealermalware-familygolangsigningobfuscation
SHA-256: ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa

acrstealer: ba1af858 — Go 1.25.4 x64, 66 randomized main.* functions, five-icon .rsrc suite (quiverquant.com/WE1 cert)

Executive Summary

Forty-fifth confirmed sibling in the ACR stealer cluster. Go 1.25.4 PE32+ x64 with module path UbaSUgsUHMKzoZw, 66 randomized main.* function names (tying the cluster record for heaviest count on the quiverquant.com/WE1 cert sub-cluster), five-icon .rsrc PNG suite, and no static C2. OpenCTI labels cloud55file-cc and neuralpulsecore5-sbs are contested; all technical fingerprints resolve to the ACR cluster.

What It Is

Attribute Value
SHA-256 ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa
Filename LJHKKUU7.exe
Size 4,386,944 bytes (4.2 MB)
Type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:1714]
Go build ID nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA ^[strings.txt:10]
Module path UbaSUgsUHMKzoZw ^[strings.txt:1718]
Randomized main.* symbols 66 (tying cluster record for heaviest on this cert chain) ^[strings.txt]
Signing Self-signed Authenticode, CN=quiverquant.com, issuer WE1 ^[pefile.txt]
.rsrc Five-icon suite (16×16, 32×32, 64×64, 128×128, 256×256 PNG) ^[binwalk.txt]
IAT surface Minimal: kernel32.dll only (43 imports) ^[pefile.txt]
Dynamic analysis Skipped — no CAPE Windows guest available ^[dynamic-analysis.md]

How It Works

Standard ACR stealer execution chain. Entry at 0x140072640 (runtime._rt0_amd64) → Go runtime init → main.main at 0x14009ad60. The 66 randomized main.* function names (10–18 chars, e.g. main.yvpfzgn, main.gmstcwihju, main.lcotzoyiwgoyj) are generated at compile time by the builder; they serve no runtime purpose other than anti-static obfuscation. ^[strings.txt]

The .rsrc section carries five PNG icon groups used for social-engineering masquerade (builder icon-toggle ON). ^[binwalk.txt:6-16] No hardcoded C2 URLs, IP addresses, or domain names are present in static strings — the family employs PRNG-seeded runtime decoding (see prng-seeded-c2-url-decoding). ^[strings.txt]

Certificate chain quiverquant.com/WE1 is now confirmed across seventeen ACR siblings (this sample is the seventeenth). The certificate is a 1024-bit RSA self-signed DV cert with a 90-day validity window. ^[pefile.txt]

This is a light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder, no .rsrc stripping. It matches the ef262340 / f251271a template exactly — only the module path and function names are rotated.

Decompiled Behavior

radare2 recovered 2,139 functions at analysis level 2. The entrypoint is standard Go runtime._rt0_amd64 (0x140072640). The main package initializes via sym.main.init (0x1400969e0), then dispatches to sym.main.main (0x14009ad60). Notable functions:

  • sym.main.yvpfzgn (0x140096a20) — early-stage init helper, called before main.main
  • sym.main.taikccnxoruw (0x140098a60) — mid-chain worker, xref'd from main.main
  • sym.main.mzrmckwquyymnwp (0x140098060) — heavy function, 15+ callees, likely data-collection orchestrator

No sym.main.encrypt, sym.main.decrypt, or custom crypto routines are visible — the build relies on Go's standard crypto/tls and crypto/x509 linkage. ^[rabin2-info.txt]

C2 Infrastructure

No static C2 recovered. Family behaviour (confirmed across 44 prior siblings) indicates PRNG-seeded runtime URL decoding after a configurable sleep gate. No domain, IP, or URL strings are present in the binary. ^[strings.txt]

Interesting Tidbits

  • Module path length: 16 chars (UbaSUgsUHMKzoZw), consistent with the 12–20 char range observed across the cluster.
  • Build timestamp: Null (0x0), standard for Go -trimpath static builds. ^[pefile.txt]
  • PE section entropy: .text 6.26, .rdata 6.78, .rsrc 7.98 — the .rsrc near-maximum entropy is expected for five compressed PNG groups. ^[pefile.txt]
  • Import surface: Only kernel32.dll is imported statically; all other Windows APIs are resolved at runtime via GetProcAddress inside the Go syscall package. ^[pefile.txt]
  • Certificate expiry: The embedded cert shows validity 2026-05-09 to 2026-08-07, placing build date in mid-2026. ^[pefile.txt]
  • OpenCTI contested labels: cloud55file-cc and neuralpulsecore5-sbs are preliminary tags with no independent technical fingerprint. Every sample bearing these labels in the corpus resolves to ACR by cert chain + Go build ID. ^[entities/cloud55filecc.md]

How To Mess With It (Homelab Replication)

Build a comparable Go binary:

GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go

Use a module path randomizer (e.g. go mod init $(openssl rand -hex 8)) and rename all exported main.* functions to random 10–18 char strings before compile. Embed a .rsrc icon suite with rsrc or goversioninfo.

Verification: rabin2 -I repro.exe should show lang: go, signed: false (or true if you add a self-signed cert), and 9+ PE sections. strings repro.exe | grep 'main\.' should show randomized names.

Deployable Signatures

YARA rule

rule ACRStealer_Go1254_x64_QuivCert {
    meta:
        description = "ACR stealer Go 1.25.4 x64 with quiverquant.com/WE1 cert chain"
        author = "PacketPursuit"
        date = "2026-08-17"
        sha256 = "ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa"
    strings:
        $go_build_id = "Go build ID: \"nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA\""
        $go_ver = "go1.25.4"
        $mod_path = "UbaSUgsUHMKzoZw"
        $cert_cn = "quiverquant.com"
        $cert_issuer = "WE1"
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        filesize > 4MB and filesize < 5.5MB and
        any of ($go_build_id, $mod_path) and
        $go_ver and
        $cert_cn and
        $cert_issuer
}

Behavioral fingerprint

This binary is a Go 1.25.4 static PE32+ x64 with a minimal IAT (kernel32.dll only), randomized main.* function names, and a five-icon .rsrc PNG suite. It launches as a Windows GUI process with no visible window, initializes the Go runtime, and contacts a C2 endpoint decoded at runtime via a PRNG-seeded string transform. No hardcoded network indicators are present in static analysis.

IOC list

Indicator Value Type
SHA-256 ba1af85880677c82be1c4388452fad1874f2edf73e5cd1521553c3710cf63ffa Hash
Filename LJHKKUU7.exe Filename
Certificate CN quiverquant.com Signing
Certificate issuer WE1 Signing
Go build ID nW5jtEF-JMrMsq_bnABx/L5XmmbuXmRpNVbsrIPYi/wcxlS5JpcphqxyJSndYD/VepQNHYnqaFnYM-I0wiA Build artefact
Module path UbaSUgsUHMKzoZw Build artefact
Go version go1.25.4 Toolchain

Detection Signatures

Technique ATT&CK ID Evidence
Standard Application Layer Protocol T1071 crypto/tls + net/http statically linked ^[strings.txt]
Ingress Tool Transfer T1105 Inferred from family behaviour (runtime C2 fetch) ^[acrstealer.md]
Data from Local System T1005 Browser/crypto wallet credential targeting (family TTP) ^[acrstealer.md]
Obfuscated Files or Information T1027 Randomized Go module path and function names ^[strings.txt]
Masquerading T1036.001 Five-icon .rsrc PNG suite for social engineering ^[binwalk.txt]
Code Signing T1553.002 Self-signed Authenticode cert CN=quiverquant.com ^[pefile.txt]

References

Provenance

  • file.txt — file command output, file(1) v5.44
  • pefile.txt — pefile Python library analysis
  • strings.txt — GNU strings v2.38
  • rabin2-info.txt — radare2 v5.9.0 rabin2 -I
  • binwalk.txt — binwalk v2.3.3
  • dynamic-analysis.md — CAPE sandbox status (skipped — no Windows guest)
  • radare2 MCP — analysis level 2, 2,139 functions recovered